5 ms·
What exactly is "Old-skool" in virus-writing and what is new-school?
by ique 16y ago
What exactly is "Old-skool" in virus-writing and what is new-school?
- Leynos 16y agoAs defined in this case, an "old-skool" virus would be one written in assembly whose primary vector of infection is by embedding itself in executable files.
- niels_olson 16y agoThat would be an element of the set, not the definition.
- gregschlom 16y agoBack in the days viruses had to hide themselves in executables to travel from machine to machine, undetected. Today, as most users don't care about what processes are running on their system, and since the most common vector of infection is through the internet, what we call "viruses" are actually worms: they don't infect other programs, they are just self-replicating, malicious, executables.
- nitrogen 16y agoIt's a shame that your parent comment isn't getting any up-votes, as your comment is informative enough to deserve a higher place on the page.
- axod 16y agoolder school: boot sector viruses which triggered when an infected floppy was left in a machine on bootup. They'd then TSR and infect any other floppys inserted into the machine, as well as any hard disk drives if the machine was an expensive newer model with a hard card.
- 16s 16y agoNew school is the web browser, JavaScript and interpreted languages (ruby, python, etc). Old school is assembly, C and C++. Like Web 2.0 versus Web 1.0. Old school isn't snazzy and exciting and has a higher entry point. You won't find many old school fart apps.
- trotsky 16y agothe network is the virus
- kschua 16y agoOld school virus. 1) They infect boot sectors of floppy and hard disk, or 2) They infect partition tables of hard disk or, 3) They infect .COM (most commonly Command.com) and .EXE Old school virus infects the executable files such that when the executable files are run, the virus stays resident in memory and infects all other executable files and floppy disks, hence the reason Command.com is the most popular target. The file size of the executable might increase when the virus infects it. To minimise this and avoid detection based on file size, the virus need to small enough to hide in the slack space, hence the reason most of them are written in assembly. To overcome boot sector virus on a floppt is easy. I made a clean copy of newly formatted MS-DOS disk and then kept a copy of Boot Sector 0 in a file which I then use to override the Boot Sector 0 in the infected floppy using Norton Diskedit. Same applies to partition tables. Executables that are infected are a pain to clean, but knowing that Command.com is most often targetted, I alway keep a clean copy of Command.com renamed as abc.def (to avoid detection by the virus) on my system. Create an entry in autoexec.bat to do a file compare between command.com and abc.def and alert me of changes. These are the problems I had cleaning old school virus. New school virus are easy to handle, they don't infect executables. They create entries in Windows startup to run themselves. Find the right entries and remove them and the virus won't be problem when you next boot up. The biggest threat I see is when some of the old school virus writers return and start infecting/corrupting executable files such as Command.com via drive-by download. Actually I working on a side project to combat new school virus. If anyone is interested, just drop me a mail via my account.